Senior AdvisoryInsuranceFintechEnergy

When the regulator asks who authorised that tracking, the answer cannot be "an AI agent."

We open with a Governance Posture Call, deliver a Governance Posture Review, run an Obscurity Governance Retainer, and operate ConsentMark Monitor as the instrument underneath.

Insurance, fintech and energy boards carry accountability for what their websites measure, under the GDPR and the ePrivacy rules their regulators enforce across the EU and the UK. Obscurity is a senior analytics governance practice for regulated organisations in Ireland and the UK. The CMP vendor and the agency that installed the tags cannot audit themselves. We have no stake in the answer, and the record we produce is written to be handed to a data protection officer, an auditor or a regulator.

Led by Dónal Troddyn
Founder & Principal. 15+ years analytics governance in regulated sectors.

The DPC's final decision against IAB Europe, issued in May 2022 and confirmed on appeal in 2025, made clear that a TCF banner in a regulated organisation needs controller-level evidence. The CMP cannot supply that evidence about itself. Code agents and release automation are changing tracking surfaces faster than a manual review cycle covers them. Obscurity gives boards and data protection officers the independent, timestamped evidence that demonstrates ongoing control of what a site ships.

Governance Posture Call, Review and Retainer

An engagement opens with a Governance Posture Call, a scoped conversation about where your tracking exposes you. It usually leads to a Governance Posture Review, which sets down in writing, on a date, what your tracking does. Beyond that, an Obscurity Governance Retainer operates the measurement layer month after month under one named contact. Scope and fees are set in the conversation.

Governance Posture Call
A scoped conversation about where your tracking exposes you, at no charge and with nothing to prepare. It suits a board member, data protection officer or CTO who has to answer for what their sites measure. It ends with a written recommendation, which is sometimes that you need nothing from us.
Governance Posture Review
A bounded piece of work for an organisation that has to answer a board, an auditor or a regulator on what its tracking does. You get a dated written finding covering what your properties ship to the browser, how consent is honoured and where the gaps sit. It is yours on delivery, to circulate without any further commitment to us.
Obscurity Governance Retainer
We run the measurement work month after month for regulated organisations whose digital properties change faster than a periodic review can follow. ConsentMark Monitor scans your properties daily and we interpret what it finds. You put your questions to the person who ran the month. It ends when you give notice, and what we hold on your properties leaves with you.

What a retained month contains

A retained month is continuous work. After each release your journeys are run again through their consent states - accept, reject, and the partial states in between. A change that alters what a page sends is caught while the release is still fresh.

Every tag change we make is staged as a version in your own container and published on your side, under your change process. The record says what changed and why. When something breaks, the evidence is captured as it happens - what fired, on which page, under which consent state - rather than reconstructed afterwards.

A written report goes out each month covering what ran, what changed and what is still open. The report names the person who ran the month, and they answer your board's or your data protection officer's questions on it when asked.

Scope of service

Included
We find what your sites are sending and remediate the tags and the containers behind it. We quantify it from the analytics data we can reach, and document it so the finding stands up on its own. This work runs under the agreed scope, without waiting for a request each time.
On request
We brief your data protection officer, your legal team or your board on what we found, and we present the record in person. We supply the factual material and the method behind it to support a response to a regulator. Preserving or extracting data from the systems we can reach falls here too, as does an analysis deeper than the month called for. You ask, we scope it, and it is quoted separately.

We do not decide whether it is notifiable. A finding is only useful to your DPO if the people who produced it had no interest in the answer.

Professional indemnity insurance is held, and at the end of an engagement your evidence is returned to you in an open format within 90 days.

Security and due diligence questions are answered on the ConsentMark security page.

How we deliver

Every engagement follows a five-stage governance lifecycle. ConsentMark provides the evidence layer: automated scans, each kept as a record.

ConsentMark
Scan
ConsentMark scans your digital properties and grades consent behaviour A through F.
ConsentMark
Identify
Every tracking tag and every gap in consent handling is recorded with the evidence behind it.
Obscurity
Govern
We design the framework, the approval workflows and the controls that hold the measurement layer in place.
Obscurity
Implement
Standards, approval processes, testing pipelines, and audit documentation are built and handed over.
ConsentMark
Monitor
Daily scanning detects drift, and we alert you when a governance control is breached. The cycle then runs again from the scan.

Regulated industries with complex digital properties

We work in sectors where a supervisory authority can ask what a website measures and expect a documented answer.

Insurance
CBI (Ireland), FCA & PRA (UK). Complex multi-brand digital properties with high marketing spend and strict data handling requirements.
Fintech
CBI, FCA. Rapid release cycles and experimentation platforms that outpace manual governance review.
Energy
CRU (Ireland), Ofgem (UK). Consumer-facing digital properties with consent complexity across metering, billing, and marketing.
Travel
DPC (Ireland), ICO (UK). High-volume booking platforms with extensive third-party tag ecosystems and cross-border data flows.
D
Dónal Troddyn
Founder, Obscurity

Every engagement is led by the founder. The work turns on technical detail and regulatory context at the same time, and on the judgement to say what a finding means for a compliance posture.


ConsentMark, our own scanning and monitoring platform, carries the measurement. It runs on a daily schedule, so the time goes on reading what a scan found rather than on collecting it.

The Governance Posture Call

The call runs 45 minutes and there is nothing to prepare. We use it to work out whether analytics governance is a priority for your organisation, and whether we are the people to do it.

Email
Registered office
71 Lower Baggot Street, Dublin 2, D02 P593, Ireland
Book a Governance Posture Call